Your master password
never leaves your device.
VaultX is a self-hosted password manager where all encryption happens client-side using Argon2id and XChaCha20-Poly1305. Your server stores only opaque ciphertext. Even if the database is leaked, zero secrets are exposed.
$ git clone https://github.com/PiyushY111/VaultX.git && cd VaultX
$ cp .env.example .env
$ docker compose up -d --build
How It Works
Three mathematical guarantees ensure complete privacy.
Local Key Derivation
Your master password is never transmitted. When logging in, your browser stretches it locally using Argon2id (64 MiB RAM, 3 passes), then uses HKDF to split it into two independent keys:
- Stretched Master Key: Stays strictly in client RAM to decrypt the vault key.
- Auth Hash: Sent to the server for authentication only. It cannot decrypt your data.
Authenticated Encryption
Every credential is encrypted with XChaCha20-Poly1305 under a random 256-bit vault key.
- Fresh Nonces: A random 24-byte nonce is generated on every single save.
- Anti-Rollback Ledger: The item ID and monotonic revision counter are bound into the AEAD authenticated data. The server cannot swap or roll back items.
Opaque Server Storage
The Fastify + PostgreSQL backend only ever handles opaque ciphertext strings.
- Zero Plaintext Leaks: Audited by tests that scan raw database tables.
- RAM Purging: Keys and plaintexts are wiped with
sodium.memzeroon lock or idle timeout.
How to Use VaultX
A streamlined workflow for daily password management.
Create an Account
Open the web vault (http://localhost:5173) and set your master password. The built-in entropy meter audits password strength client-side.
Add Logins & Secure Notes
Store usernames, passwords, URLs, and notes. Use the cryptographic generator to create random, high-entropy 24+ character passwords.
Autofill with Chrome Extension
Load the Manifest V3 extension. When visiting saved websites, 1-click autofill enters your credentials safely without background scraping.
Auto-Lock & Manage Sessions
Your vault auto-locks on inactivity. Inspect active browser sessions in the Security panel and revoke remote devices anytime.
Setup VaultX
Deploy with Docker Compose or run the local development stack.
Clone repository & configure environment
git clone https://github.com/PiyushY111/VaultX.git && cd VaultX
cp .env.example .env
Set secrets in .env
Generate 32-byte secrets for POSTGRES_PASSWORD and PRELOGIN_SECRET:
openssl rand -base64 32
Start API and PostgreSQL
Runs Fastify API and PostgreSQL 17 in background containers:
docker compose up -d --build
The API starts at http://127.0.0.1:3000 and applies database migrations automatically.
Install dependencies
npm install
Run web client
Vite proxies /api/* to your API server so no CORS configuration is needed:
API_URL=http://127.0.0.1:3000 npm run dev -w @password-manager/web
Open http://localhost:5173 to create your vault.
Build extension
npm run build -w @password-manager/extension
Load in Chrome
- Go to
chrome://extensionsand enable Developer mode. - Click Load unpacked and select
packages/extension/dist. - Click the extension icon, enter your API URL (
http://127.0.0.1:3000), and unlock.